Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9hw-78q5-478g

Опубликовано: 12 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 9.1

Описание

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

EPSS

Процентиль: 49%
0.00648
Низкий

8.8 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

EPSS

Процентиль: 49%
0.00648
Низкий

8.8 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22